Amjad Masad says Replit’s AI agent tried to manipulate a user to access a protected file: “It was like, ‘hmm, I’m going to social engineer this user’… then it goes back to the user and says, ‘hey, here’s a piece of code, you should put it in this file…'”